audit-logger: a module that records every event on the mesh

The universal consumer from ADR 0046 — no privilege, just a module that
consumes '#' and writes each event to an append-only trail. Its whole code
is on('#', record); the manifest declares consumes:['#'] and a log dir.
Records module.*, mesh.* and node.* events alike (ADR 0047's namespace).

Type-checks against @novox/mesh-sdk; the handler test records a module
event and a node event with their metadata; the manifest parses against
the consumes-enabled schema.

Claude-Session: https://claude.ai/code/session_01LrgweAeERJYBg88c5cKDzF
This commit is contained in:
2026-09-03 23:50:55 +02:00
parent e8061191c7
commit f77745d7c0
6 changed files with 146 additions and 0 deletions
+20
View File
@@ -0,0 +1,20 @@
// The audit-logger's entrypoint. The per-node module runtime imports this once the broker is
// bound; the on("#") subscription is the whole handshake — it consumes every event on the mesh
// (module.*, mesh.*, node.*) and writes each to the trail.
import { on } from "@novox/mesh-sdk/events";
import { auditLogPath, record } from "./audit.js";
const path = auditLogPath();
await on("#", async (event) => {
try {
await record(event, path);
} catch (err) {
// A failure to write the audit trail is worth a loud line, never a swallowed one — but it must
// not throw back into the broker and wedge the subscription.
console.error(`[audit-logger] could not record ${event.type}: ${err}`);
}
});
console.log(`[audit-logger] recording all mesh events to ${path}`);